rule
[
rule-id
] {
deny
|
permit
} {
udp
|
protocol-number
} [
destination
{
destination-ipv6-address
prefix-length
|
destination-ipv6-address/prefix-length
|
postfix
postfix-length
|
any
} |
destination-port
{
eq
|
gt
|
lt
|
range
}
port
|
dscp
dscp
|
fragment
|
logging
|
precedence
precedence
|
source
{
source-ipv6-
address
prefix-length
|
source-ipv6-address/prefix-length
|
source-ipv6-address
postfix
postfix-length
|
any
} |
source-port
{
eq
|
gt
|
lt
|
range
}
port
|
time-
range
time-name
|
tos
tos
]
*
–
When
protocol
is set to ICMPv6, the command format of an advanced ACL6 rule
is as follows:
rule
[
rule-id
] {
deny
|
permit
} {
icmpv6
|
protocol-number
} [
destination
{
destination-ipv6-address
prefix-length
|
destination-ipv6-address/prefix-length
|
postfix
postfix-length
|
any
} |
dscp
dscp
|
fragment
|
icmp6-type
{
icmp6-type-
name
|
icmp6-type
icmp6-code
} |
logging
|
precedence
precedence
|
source
{
source-ipv6-address
prefix-length
|
source-ipv6-address/prefix-length
|
source-
ipv6-address
postfix
postfix-length
|
any
} |
time-range
time-name
|
tos
tos
]
*
–
When
protocol
is set to other protocols, the command format of an advanced ACL6
rule is as follows:
rule
[
rule-id
] {
deny
|
permit
} {
protocol-number
|
gre
|
ipv6
|
ospf
}
[
destination
{
destination-ipv6-address
prefix-length
|
destination-ipv6-address/
prefix-length
|
destination-ipv6-address
postfix
postfix-length
|
any
} |
dscp
dscp
|
fragment
|
logging
|
precedence
precedence
|
source
{
source-ipv6-
address
prefix-length
|
source-ipv6-address/prefix-length
|
source-ipv6-address
postfix
postfix-length
|
any
} |
time-range
time-name
|
tos
tos
]
*
5.
Run:
quit
Return to the system view.
6.
Run:
traffic classifier
classifier-name
[
operator
{
and
|
or
} ]
A traffic classifier is created and the traffic classifier view is displayed.
The
and
parameter indicates that the relationship between rules in a traffic classifier
is AND. That is, packets match a traffic classifier only when the packets match all
non-ACL rules and an ACL rule in the traffic classifier. The
or
parameter indicates
that the relationship between rules in a traffic classifier is OR. That is, packets match
a traffic classifier when the packets match a rule in the traffic classifier.
By default, the relationship between rules in a traffic classifier is AND.
7.
Run:
if-match
acl
advanced-acl-number
A traffic classifier based on an advanced ACL is created.
l
Creating a traffic classifier based on a Layer 2 ACL
1.
Run:
system-view
The system view is displayed.
2.
Run:
acl
l2-acl-number
A Layer 2 ACL is created and the ACL view is displayed.
S3700HI Ethernet Switches
Configuration Guide - QoS
1 Class-based QoS Configuration
Issue 01 (2012-03-15)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
16